2 The Time-Based Security Model of Auditors have ong recognized that preventive controls can never provide 100% pro tection. Give preventive control can be circum- enough time and resources, any vented. Consequent effective control requires supplementing preventive procedures with methods for for corrective remedial detecting incidents and procedures taking action. Moreover, the detection and corrective actions must be timely. This is espe- cially important for information security. because once preventive controls have been breached, it takes little tim compromise, steal the organization's eco to destroy, o nomic and information resources. The time-based model of security focuses on the relationship between preventive, detective, and corrective controls. All three types of controls are necessary. The role of preventive controls is to limit actions to those in accord with the organization's security policy and to not allow undesired actions. The role of detective controls is to identify when preventive controls have been breached. The role of corrective controls is to repair damage from any problems that occurred and to improve the functioning of both preventive and detective controls in order to reduce the likelihood of future problems. The time-based model of security evaluates the effectiveness of an organization's security by measuring and comparing the relationship among the following three variables
P-the time it takes an attacker to break through the organization's preventive controls
D-the time it takes to detect that an attack is in progress
c-the time it takes to respond to the attack